CVE-2024-32848
largeAuthenticated SQL Injection Leading to RCE in Ivanti Endpoint Manager
Ivanti Endpoint Manager (EPM) contains an SQL injection flaw (CWE-89) that an authenticated attacker with administrator-level privileges can trigger over the network to execute arbitrary code on the EPM core server. Because it requires high privileges and no user interaction, exploitation would likely involve stolen or compromised admin credentials, potentially chained with other EPM flaws, and grants the attacker full confidentiality, integrity and availability impact on the server. All deployments running versions before 2022 SU6, and 2024-release versions before the September 2024 update, are affected. Ivanti has released fixes (2022 SU6 and the September 2024 update), and the flaw carries an elevated near-term exploitation risk (EPSS 43.4%, 99th percentile), though it is not yet in CISA's KEV catalog and no public proof-of-concept is known.
What to do: Upgrade Ivanti EPM core servers to 2022 SU6 or apply the September 2024 update, prioritizing internet-exposed consoles given the high EPSS score. Until patched, restrict access to the EPM web console to trusted networks, audit EPM administrator accounts for weak or default credentials, and review logs for unusual console or database activity.
| Ivanti Endpoint Manager (EPM) | All versions before 2022 SU6; for the 2024 release, all versions before the September 2024 update (fixed in 2022 SU6 and the September 2024 update) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
- Vendors
- ivanti
- Products
- endpoint manager
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H